Authorization bypass through user-controlled key in ZooKeeper - CVE-2023-44981

 

Authorization bypass through user-controlled key in ZooKeeper - CVE-2023-44981

Published: November 20, 2023


Vulnerability identifier: #VU83312
CSH Severity: Medium
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-44981
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authorization process.

The vulnerability exists due to improper implementation of SASL Quorum Peer authentication. The instance part in SASL authentication ID, which is listed in zoo.cfg server list, is optional and if it's missing, the authorization check will be skipped. As a result an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree.


Affected software

ZooKeeper
Debian Linux
Ubuntu
IBM Operations Analytics Predictive Insights
IBM Process Mining
IBM SPSS Analytic Server
IBM Watson Discovery for IBM Cloud Pak for Data
Oracle Communications Cloud Native Core Network Data Analytics Function
QRadar User Behavior Analytics
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Cloud Pak for Business Automation
IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library
IBM Observability with Instana
IBM Cloud Pak for Multicloud Management
Primavera Unifier
IBM Db2 Web Query for i
Oracle Banking Virtual Account Management
Oracle Banking Origination
Oracle Banking Liquidity Management
Oracle Banking Cash Management
Oracle Banking Branch
Oracle Banking Corporate Lending Process Management
Oracle Banking Supply Chain Finance
Oracle Banking Trade Finance Process Management
AMQ Streams
AMQ Broker
Spring for Apache Kafka
IBM Cloud Pak for Watson AIOps
DataStage on Cloud Pak for Data
IBM Application Suite - IBM Asset Data Dictionary Component
IBM Planning Analytics Workspace
Cloud Pak for Network Automation
Netezza Performance Server Replication Services
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
User Entity Behavior Analytics
StreamSets Data Collector
Communications Service Catalog and Design
Juniper Secure Analytics (JSA)
IBM Security Guardium
libzookeeper-java (Ubuntu package)
zookeeper (Debian package)
watsonx.data
IBM Qradar SIEM
Event Streams
Operational Decision Manager
IBM Cognos Analytics

How to mitigate CVE-2023-44981

Install updates from vendor's website.

ZooKeeper - addressed in versions 3.7.2, 3.8.3, 3.9.1
IBM Operations Analytics Predictive Insights - update to 1.3.6.8
IBM Process Mining - update to 1.14.3
IBM Cloud Pak for Multicloud Management - update to 2.3.8
AMQ Streams - addressed in versions 2.5.2, 2.6.0
Spring for Apache Kafka - addressed in versions 3.0.13, 3.1.0
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.0
DataStage on Cloud Pak for Data - update to 5.2.0
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF05
AMQ Broker - addressed in versions 7.10.6, 7.11.6, 7.12.0
libzookeeper-java (Ubuntu package) - addressed in versions Ubuntu Pro, 3.4.13-5ubuntu0.1, 3.4.13-6ubuntu4.1, 3.8.0-10ubuntu0.1, 3.8.0-11ubuntu0.1
IBM Application Suite - IBM Asset Data Dictionary Component - update to 1.1.8
watsonx.data - update to 2.0.3
IBM Planning Analytics Workspace - update to 2.0.93
Cloud Pak for Network Automation - update to 2.6.4
Netezza Performance Server Replication Services - update to 3.0.5.0
zookeeper (Debian package) - addressed in versions 3.4.13-6+deb11u1, 3.8.0-11+deb12u1
QRadar User Behavior Analytics - update to 4.1.16
IBM Watson Assistant for IBM Cloud Pak for Data - update to 4.8.5
DB2 on Cloud Pak for Data - update to 4.8.5
DB2 Warehouse on Cloud Pak for Data - update to 4.8.5
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.9, 5.1.3
User Entity Behavior Analytics - update to 5.0.2
StreamSets Data Collector - update to 7.0.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF05
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 47, 8.11.0.1 Interim fix 25, 8.11.1 Interim fix 15, 8.12.0 Interim fix 6
IBM Cognos Analytics - addressed in versions 11.2.4 FP3, 12.0.3
Event Streams - update to 11.3.1
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.27, 23.0.1.5
IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library - update to 38.4
IBM Observability with Instana - update to 283

External References

Related Security Bulletins